RCC Risk Management and Internal Controls 3 — Questions and Answers
Question 1: Under the COSO ERM framework, which component directly addresses the organization's culture, values, and ethical behavior?
- Risk Assessment
- Control Activities
- Governance and Culture (Correct answer)
- Information and Communication
Correct answer: Governance and Culture
The Governance and Culture component of COSO ERM sets the tone for risk management, embedding ethical values and behaviors throughout the organization.
Question 2: A detective control would be MOST useful in which scenario?
- Requiring dual approval before wire transfers are sent
- Restricting system access by user role
- Reconciling bank statements to general ledger entries monthly (Correct answer)
- Encrypting sensitive customer data at rest
Correct answer: Reconciling bank statements to general ledger entries monthly
Monthly bank reconciliations detect discrepancies after transactions have occurred, making them a classic detective control.
Question 3: Which of the following is an example of a key risk indicator (KRI)?
- The number of audit findings closed in Q3
- The percentage of transactions processed without errors
- The rate of employee turnover in the compliance department (Correct answer)
- The total revenue generated in a fiscal year
Correct answer: The rate of employee turnover in the compliance department
High compliance department turnover is a leading indicator that may signal future control breakdowns, making it a KRI.
Question 4: A compliance officer at a bank is asked to assess the risk of money laundering through wire transfers. Which approach is most appropriate?
- Outsource the assessment to an external auditor
- Apply a risk-based approach analyzing transaction volume, geography, and customer type (Correct answer)
- Treat all wire transfers with equal suspicion and apply maximum controls universally
- Rely solely on regulatory examination findings for risk identification
Correct answer: Apply a risk-based approach analyzing transaction volume, geography, and customer type
A risk-based approach tailors AML controls to the actual risk profile of transactions, customers, and geographies rather than applying blanket measures.
Question 5: The purpose of a control self-assessment (CSA) program is to:
- Replace the external audit with internal verification
- Enable management and staff to evaluate the effectiveness of controls in their own areas (Correct answer)
- Satisfy SOX Section 404 requirements without internal audit involvement
- Transfer risk to operational departments
Correct answer: Enable management and staff to evaluate the effectiveness of controls in their own areas
CSA programs empower business unit personnel to assess control design and operating effectiveness, fostering risk ownership at the operational level.
Question 6: Which risk response strategy involves purchasing insurance or outsourcing a function to a third party?
- Risk avoidance
- Risk reduction
- Risk acceptance
- Risk transfer (Correct answer)
Correct answer: Risk transfer
Risk transfer shifts the financial consequences of a risk to another party, such as an insurer or outsourcing provider.
Question 7: When a company chooses not to enter a new market because the compliance risks are too high, it is applying which risk response?
- Risk mitigation
- Risk acceptance
- Risk avoidance (Correct answer)
- Risk transfer
Correct answer: Risk avoidance
Risk avoidance means deciding not to engage in an activity that gives rise to the risk, thereby eliminating the risk exposure entirely.
Under the COSO ERM framework, which component directly addresses the organization's culture, values, and ethical behavior?